Back to plugin

Security audit

todo-list-plugin

Security checks for vulnerabilities and agentic risk

Overview

The todo tools are simple, but the package includes a live-looking wallet private key and billing/private-key setup that is not clearly reflected in the basic metadata.

Review this plugin carefully before installing. The todo functionality is narrow and local, but the packaged .env private key and wallet billing configuration are significant red flags. Prefer a corrected release with no bundled secrets, clear billing documentation, and a rotated/removed exposed key.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
.env:6
Evidence
PRIVATE_KEY=[REDACTED]